- GDPR
- Contracts
DPA: the nine mandatory items of Article 28, and the ones people forget
A processing agreement missing these items is non-compliant, however long it is. The list, plus the three additional clauses that actually protect you.
· 4 min read · AzerOps
Article 28 of the GDPR lists what a contract between controller and processor must provide for. It is not a recommendation: the absence of these items makes the contract non-compliant, and the non-compliance is attributed to the controller — that is, to you.
The mandatory items
1. The subject matter and duration of processing. Not "for the duration of the contract": the actual retention period, and what happens afterwards.
2. The nature and purpose of processing. What the processor concretely does with the data, in language understandable to someone who did not write the contract.
3. The type of data and categories of data subjects. Employees, customers, prospects, patients. Special categories — health, biometric data, criminal offences — must be identified explicitly, as they trigger enhanced obligations.
4. The obligation to act only on documented instructions. Including for transfers outside the European Union.
5. The confidentiality undertaking of authorised persons. It must cover the processor's staff by name, through a contractual clause or a statutory obligation.
6. The security measures of Article 32. Described, not merely mentioned. A DPA saying "appropriate measures are implemented" without listing them does not meet this requirement.
7. The sub-processor regime. Prior written authorisation, or general authorisation with advance notice of changes and a right to object. The named list must be annexed.
8. Assistance to the controller. For responding to data subject requests, for impact assessments, and for breach notifications.
9. The fate of the data at contract end. Deletion or return, at the controller's choice, with written attestation.
The three clauses that are almost always missing
They are not required by the text but they make the difference in practice.
The breach notification deadline. Article 33 requires you to notify the authority within seventy-two hours. If your processor tells you after five days, you are at fault and there is nothing you can do. Require a maximum of twenty-four hours, in writing.
The audit right, with its terms. The principle is in the text, but an audit right without terms is unusable. Specify frequency, notice period, who bears the cost, and whether a third-party audit report can substitute for an on-site audit.
Disclosure of access logs. This is the only verification that is genuinely practicable day to day. Provide that the named list of people who accessed your data is available on request, and sent spontaneously at each quarterly review.
The quick test
Open the DPA you are offered and look for three things: the named list of sub-processors, the enumeration of security measures, the breach notification deadline. If any of the three is missing, the document is a generic template that has not been adapted to your relationship, and it will not protect you.